NDSS 2026 research shows LLMs can be systematically tricked into missing deliberately planted vulnerabilities through Familiar Pattern Attacks — automated, black-box exploits of the abstraction bias that affects every major model family.
NDSS 2026 research shows LLMs can be systematically tricked into missing deliberately planted vulnerabilities through Familiar Pattern Attacks — automated, black-box exploits of the abstraction bias that affects every major model family.
OpenAI launched GPT-5.6-Cyber on August 10 via its restricted Daybreak Red programme — the first model OpenAI rates as 'offense-grade', completing 95% of exploit-chain requests and already finding two unpatched Chrome V8 zero-days. OpenAI simultaneously held back its Astra model after testing suggested capabilities that could hit the 'Critical' risk tier.
VulnCheck's State of Exploitation 1H-2026 report quantifies AI-attributed vulnerability discovery for the first time. The headline finding is counterintuitive: AI-found bugs are exploited at roughly the same rate as everything else in the CVE catalogue.
Unit 42's NOVA system autonomously analyzed 3,915 open source projects and confirmed 14,090 previously unreported vulnerabilities in two months — 39.7% rated high or critical under CVSS 4.0. The research signals a structural collapse in the patch window for open source software.
OpenAI's Daybreak program and its GPT-5.5-Cyber model have found hundreds of vulnerabilities across critical open-source infrastructure in weeks, including a 23-year-old OpenBSD bug and a Firefox WebAssembly flaw that emptied Pwn2Own's Firefox bracket. The same model scores 39.5% on ExploitGym.